
Is it illegal to send promotional emails?
Key Facts
- ["Verkada paid $2.95 million in 2024—the largest CAN-SPAM settlement in FTC history—for sending 30 million emails with no opt-out", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"], ["GDPR fines exceeded €1.2 billion in one year, with maximum penalties up to €20 million or 4% of global revenue", "https://www.mailforge.ai/blog/gdpr-vs-can-spam"], ["CASL allows fines of up to $10 million CAD per violation for organizations, and individuals can sue directly", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"], ["Under CAN-SPAM, the FTC updated the fine to $53,088 per violating email in January 2025—not per campaign", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"], ["Since February 2024, Gmail has permanently rejected bulk senders who fail email authentication or lack a one-click unsubscribe", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"], ["Over 300 CAN-SPAM cases have been filed with the FTC to date", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"], ["Experian settled for $650,000 due to a broken unsubscribe flow during a platform migration", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"]]
Why Promotional Emails Without Consent Are Risky — Even in the US
Many US business owners assume that because CAN-SPAM permits unsolicited commercial email, they can send promotional messages freely. That assumption is expensive: the law allows sending first, but it demands strict requirements in every message, and the penalties are severe.
Under CAN-SPAM, you don't need consent before emailing a US recipient — but every commercial email must meet seven specific requirements, including accurate sender information, no deceptive subject lines, a valid physical postal address, and a functional unsubscribe mechanism. You must honor opt-out requests within 10 business days, keep the unsubscribe option valid for at least 30 days after sending, and never charge a fee or require a login to process an opt-out, per FTC guidance. You also remain legally responsible even when a third-party vendor sends the campaign on your behalf, as legal analysis of email and text compliance makes clear.
The penalties scale in a way most owners don't expect. The FTC updated the fine in January 2025 to $53,088 per violating email — not per campaign, per individual message, according to email marketing law research. A 10,000-recipient campaign sent without a working opt-out could theoretically expose a business to over $500 million in penalties, one comparison of GDPR and CAN-SPAM notes. Enforcement is real, not theoretical:
- Verkada paid $2.95 million in 2024 — the largest CAN-SPAM settlement in FTC history — for sending 30 million emails over three years with no opt-out, no physical address, and ignored unsubscribe requests.
- Experian settled for $650,000 because a broken unsubscribe flow during a platform migration went unnoticed.
- Over 300 CAN-SPAM cases have been filed with the FTC to date.
Notably, neither company set out to break the law. Experts observing these cases describe them as operational blind spots — compliance gaps that quietly develop during a redesign or email platform switch when nobody is specifically watching.
Here's the part that catches US businesses off guard: the applicable law follows the recipient, not your company address. A US business emailing someone in Germany must comply with GDPR for that contact, and GDPR requires explicit opt-in consent before anything is sent — with fines up to €20 million or 4% of global revenue. A recipient in Canada triggers CASL, which carries penalties up to $10 million CAD per violation. Where your office sits is irrelevant, which is why segmenting your list by recipient location matters.
This is why CallMyCustomers works only from lists of real customers with every message approved by the owner first — reactivating people who already know your business is both the most profitable and the most defensible place to run outreach. If you'd like a free review of what your customer list could produce, with your rate and setup quoted upfront, start with the insights hub and see how a permission-based reactivation campaign fits your repeat-revenue cycle.
Global Consent Standards: When Opt-In Is Required by Law
Sending promotional emails without proper consent isn't just risky—it's illegal in many parts of the world. Laws like GDPR in the EU, CASL in Canada, and PECR in the UK require businesses to obtain explicit opt-in permission before sending marketing messages to recipients in those regions. This means a U.S.-based company emailing someone in Germany must comply with GDPR for that recipient, regardless of where the sender is located. The law follows your recipient, not your company address, making geographic compliance essential for any business with international contacts.
For CallMyCustomers, which helps U.S. service businesses reactivate past customers through approved email and text campaigns, this means ensuring consent standards are met based on where each recipient resides. Under GDPR, fines can reach up to €20 million or 4% of global annual revenue—whichever is higher—for violations involving improper consent. GDPR fines exceeded €1.2 billion in one year, demonstrating how seriously regulators treat consent breaches. Similarly, CASL in Canada allows fines of up to $10 million CAD per violation for organizations, with individuals even able to sue directly for non-compliance. These penalties aren't theoretical; they've been enforced against major companies for failures like missing unsubscribe options or using deceptive tactics.
- GDPR requires "clear, affirmative action" for consent—pre-checked boxes are prohibited under EU law.
- CASL mandates express consent that doesn't expire unless the recipient withdraws it, unlike implied consent which fades after six months to two years.
- PECR in the UK aligns closely with GDPR, requiring opt-in for promotional emails and enforcing fines through the Information Commissioner's Office.
Even if a business operates solely in the U.S., emailing international customers triggers these stricter consent rules. Ignoring them risks not only financial penalties but also deliverability issues, as platforms like Gmail now block senders who fail authentication or lack a working one-click unsubscribe—standards that overlap with legal requirements. For service businesses relying on repeat revenue, respecting consent isn't just about avoiding fines; it's about building trust. When customers know they’ve genuinely opted in, they’re more likely to engage—turning compliance into a foundation for stronger, permission-based relationships.
How CallMyCustomers Ensures Compliant Reactivation Campaigns for US Service Businesses
CallMyCustomers ensures compliant reactivation campaigns by anchoring every outreach in explicit, verifiable consent—aligning with both U.S. CAN-SPAM requirements and global opt-in standards like GDPR and CASL. The company begins by reviewing and segmenting client lists based on recency, past interactions, and service history, ensuring only legitimate customer data is used for reactivation efforts. Before any message is sent, clients approve all scripts, offers, and content, maintaining full control over what communicates on their behalf. This permission-based model directly addresses the core legal principle that sending promotional emails without consent is illegal in most jurisdictions, where regulations like GDPR and CASL require explicit opt-in before any marketing communication can occur.
For U.S.-based recipients, CallMyCustomers adheres to CAN-SPAM’s opt-out framework by including accurate sender information, a valid physical address, and a functional unsubscribe mechanism in every email—honoring opt-out requests within 10 business days as legally required. The company further strengthens compliance by implementing double opt-in processes where appropriate, recognizing it as the “gold standard for compliance” under GDPR and a best practice for verifiable consent across regions. All email campaigns are sent with proper authentication (SPF/DKIM/DMARC) to meet deliverability standards enforced by providers like Gmail, which since February 2024 has permanently rejected bulk senders lacking these technical safeguards or a working one-click unsubscribe link.
In health-sector verticals such as dental, med spa, and wellness clinics, CallMyCustomers operates under strict privacy protocols, including HIPAA-compliant handling of protected health information and separate written authorization for any marketing content containing PHI. Outreach to these clients occurs only under valid business associate agreements (BAAs) and with messaging that meets clinical standards for patient communication. By combining client-approved messaging, immediate opt-out honoring, geographic list segmentation for global recipients, and rigorous consent tracking, CallMyCustomers turns reactivation into a repeatable, compliant revenue stream—helping US service businesses re-engage past customers without risking regulatory penalties or deliverability issues. This approach transforms compliance from a legal necessity into a trust-building advantage, ensuring every reactivation effort feels useful, not pushy.
Frequently Asked Questions
Is it actually illegal to send promotional emails without consent in the US?
Do I need consent before emailing customers in other countries?
Has anyone actually been fined for CAN-SPAM violations, or is this just theoretical?
How quickly do I have to honor unsubscribe requests?
Is a pre-checked signup box enough to count as consent?
Can my emails get blocked even if I'm legally compliant?
Turn Compliance Into Your Competitive Edge
Sending promotional emails without proper consent isn't just a legal risk—it's a costly operational blind spot that can lead to fines exceeding $500 million for a single campaign, damaged deliverability, and eroded customer trust. Whether you're navigating CAN-SPAM in the U.S., GDPR in Europe, or CASL in Canada, the law follows your recipient, not your business location, making geographic segmentation and verifiable consent non-negotiable. For US service businesses, the safest and most profitable path forward is reactivating customers who already know and trust you—using explicit, approved outreach that turns compliance into a relationship-building advantage. If you'd like to see what your customer list could generate with a permission-based reactivation campaign, start with a free list review and get your rate and setup quoted upfront. Visit the insights hub to explore how compliant reactivation fits your repeat-revenue cycle.